CVE-2026-4794: Multiple cross-site scripting (XSS) vulnerabilities in PaperCut NG/MF
Multiple cross-site scripting (XSS) vulnerabilities in PaperCut NG/MF before 25.0.10 allow authenticated administrator users to inject arbitrary web script or HTML code via different UI fields. This could be used to compromise other admininistrator's sessions or perform unauthorized actions via the administrator's authenticated context (e.g. requires an active login session).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4794?
CVE-2026-4794 is classified as a high severity vulnerability due to its potential to allow authenticated users to execute arbitrary scripts.
How do I fix CVE-2026-4794?
To fix CVE-2026-4794, upgrade your PaperCut NG or MF installations to version 25.0.10 or later.
Who is affected by CVE-2026-4794?
CVE-2026-4794 affects authenticated administrator users of PaperCut NG and MF versions prior to 25.0.10.
What types of attacks can CVE-2026-4794 enable?
CVE-2026-4794 can enable cross-site scripting (XSS) attacks, which allow attackers to inject malicious scripts into web pages.
Is authentication required to exploit CVE-2026-4794?
Yes, CVE-2026-4794 requires authenticated access for exploitation, which limits the attack vector to authorized users.